Due to unrestricted access to the Meta Model
Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks
on the application, which may prevent legitimate users from accessing it. This
can result in no impact on confidentiality and integrity but a high impact on
the availability of the application.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3460407 | Permissions Required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html | Patch Vendor Advisory |
https://me.sap.com/notes/3460407 | Permissions Required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 09:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://me.sap.com/notes/3460407 - Permissions Required | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html - Patch, Vendor Advisory |
09 Aug 2024, 19:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:netweaver_application_server_java:mmr_server_7.5:*:*:*:*:*:*:* | |
References | () https://me.sap.com/notes/3460407 - Permissions Required | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html - Patch, Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
First Time |
Sap
Sap netweaver Application Server Java |
11 Jun 2024, 13:54
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Jun 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
11 Jun 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-11 03:15
Updated : 2024-11-21 09:19
NVD link : CVE-2024-34688
Mitre link : CVE-2024-34688
CVE.ORG link : CVE-2024-34688
JSON object : View
Products Affected
sap
- netweaver_application_server_java
CWE